Vulnerability Description
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pimcore | Pimcore | >= 6.0.0, < 6.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/pimcore/pimcore/commit/e0b48faf7d29ce43a98825a0b230e88350ebcfPatchThird Party Advisory
- https://github.com/pimcore/pimcore/compare/v6.2.3...v6.3.0PatchThird Party Advisory
- https://github.com/pimcore/pimcore/commit/e0b48faf7d29ce43a98825a0b230e88350ebcfPatchThird Party Advisory
- https://github.com/pimcore/pimcore/compare/v6.2.3...v6.3.0PatchThird Party Advisory
FAQ
What is CVE-2019-18982?
CVE-2019-18982 is a vulnerability with a CVSS score of 6.1 (MEDIUM). bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
How severe is CVE-2019-18982?
CVE-2019-18982 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18982?
Check the references section above for vendor advisories and patch information. Affected products include: Pimcore Pimcore.